Forum Discussion
mf5
Nimbostratus
Aug 27, 2018APM Kerberos authentication
Hello,
Presently we have webmail using 2F-authentication (AD & OTP)
i want to know whether client side authentication uses kerberos between APM and AD?
Thanks.
Stanislas_Piro2
Cumulonimbus
Aug 28, 2018To complete Kevin’s answer
- AD auth authenticate user with session variables
andsession.logon.last.usernamesession.logon.last.password - AD Query request user attributes with LDAP filter
except if you customize the filter in VPE AD Query box.sAMAccountName=${session.logon.last.username}
You can provision these variables with
- logon pages
- 401 response pages
- variable assign box
- irules
When working with clientside Kerberos, ntlm, saml or oauth, the password variable is not provisionned because it is not received by APM.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
